nixos/wrappers: enforce target executable is ELF

This *will* break some things, such as `nixosTests.espanso`.
This is intended: Loading bash, python or perl scripts via SUID or extensive capabilities is dangerous.
PERL5LIB, PYTHONPATH or BASH_ENV make these things trivial LPE primitives.

The mime types being matched include both static, non-static and pie ELFs.
This should be fine until we somehow get yet another type of magic and associated mime type.
This commit is contained in:
Grimmauld
2026-09-28 17:19:17 +02:00
parent 10eda59563
commit 1be4b4866d

View File

@@ -361,16 +361,19 @@ in
###### wrappers consistency checks
system.checks = lib.singleton (
pkgs.runCommandLocal "ensure-all-wrappers-paths-exist"
pkgs.runCommandLocal "ensure-wrapper-integrity"
{
nativeBuildInputs = [ pkgs.libcap-text-verifier ];
nativeBuildInputs = [
pkgs.libcap-text-verifier
pkgs.file
];
preferLocalBuild = true;
}
''
# make sure we produce output
mkdir -p $out
echo -n "Checking that Nix store paths of all wrapped programs exist... "
echo -n "Checking that Nix store paths of all wrapped programs exist and are ELF executables... "
${lib.toShellVar "wrappers" (lib.mapAttrs (n: v: v.source) wrappers)}
for name in "''${!wrappers[@]}"; do
path="''${wrappers[$name]}"
@@ -382,6 +385,15 @@ in
test -t 1 && echo -ne '\033[0m'
exit 1
fi
magic=$(file --mime --brief --dereference "$path")
if ! [[ "$magic" =~ application/x-executable || "$magic" =~ application/x-pie-executable ]]; then
test -t 1 && echo -ne '\033[1;31m'
echo "FAIL"
echo "The target executable $path is not an ELF! This is a security risk."
echo "Script wrappers (e.g. bash or python) are commonly susceptible to dangerous env var injections."
test -t 1 && echo -ne '\033[0m'
exit 1
fi
done
echo "OK"